Skip to content

feat: add certs when sending requests to TrustyAIService#266

Merged
rnetser merged 1 commit intoopendatahub-io:mainfrom
adolfo-ab:add-trustyai-certs
Apr 29, 2025
Merged

feat: add certs when sending requests to TrustyAIService#266
rnetser merged 1 commit intoopendatahub-io:mainfrom
adolfo-ab:add-trustyai-certs

Conversation

@adolfo-ab
Copy link
Copy Markdown
Contributor

@adolfo-ab adolfo-ab commented Apr 24, 2025

Add certs when sending requests to TrustyAIService

How Has This Been Tested?

Running the tests against a working cluster

Merge criteria:

  • The commits are squashed in a cohesive manner and have meaningful messages.
  • Testing instructions have been added in the PR body (for PRs involving changes that are not immediately obvious).
  • The developer has manually tested the changes and verified that the changes work

Summary by Sourcery

Add SSL certificate verification when sending requests to TrustyAI Service

New Features:

  • Implement certificate-based verification for HTTPS requests to TrustyAI Service

Enhancements:

  • Improve security by using proper SSL certificate verification instead of bypassing verification

Tests:

  • Verified changes work against a working cluster

Summary by CodeRabbit

  • Bug Fixes
    • Improved security for HTTPS requests by enabling server certificate verification using a generated CA bundle file.

@adolfo-ab adolfo-ab requested a review from a team as a code owner April 24, 2025 07:25
@sourcery-ai
Copy link
Copy Markdown

sourcery-ai bot commented Apr 24, 2025

Reviewer's Guide by Sourcery

This pull request adds certificate verification when sending requests to TrustyAIService. It introduces a method to create a certificate authority bundle file and modifies the request sending logic to include the certificate path for verification.

No diagrams generated as the changes look simple and do not need a visual representation.

File-Level Changes

Change Details Files
Added certificate path to the request verification to TrustyAIService.
  • Added a method to create a certificate authority bundle file.
  • Modified the request to include the certificate path for verification.
tests/model_explainability/trustyai_service/trustyai_service_utils.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link
Copy Markdown

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @adolfo-ab - I've reviewed your changes - here's some feedback:

Overall Comments:

  • Consider extracting the base_kwargs construction into a separate function for better readability.
Here's what I looked at during the review
  • 🟢 General issues: all looks good
  • 🟢 Security: all looks good
  • 🟢 Testing: all looks good
  • 🟢 Complexity: all looks good
  • 🟢 Documentation: all looks good

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@github-actions
Copy link
Copy Markdown

The following are automatically added/executed:

  • PR size label.
  • Run pre-commit
  • Run tox
  • Add PR author as the PR assignee

Available user actions:

  • To mark a PR as WIP, add /wip in a comment. To remove it from the PR comment /wip cancel to the PR.
  • To block merging of a PR, add /hold in a comment. To un-block merging of PR comment /hold cancel.
  • To mark a PR as approved, add /lgtm in a comment. To remove, add /lgtm cancel.
    lgtm label removed on each new commit push.
  • To mark PR as verified comment /verified to the PR, to un-verify comment /verified cancel to the PR.
    verified label removed on each new commit push.
  • To Cherry-pick a merged PR /cherry-pick <target_branch_name> to the PR. If <target_branch_name> is valid,
    and the current PR is merged, a cherry-picked PR would be created and linked to the current PR.
Supported labels

{'/lgtm', '/wip', '/verified', '/hold'}

@adolfo-ab
Copy link
Copy Markdown
Contributor Author

/verified

@opendatahub-tests-bot opendatahub-tests-bot added the Verified Verified pr in Jenkins label Apr 24, 2025
@adolfo-ab
Copy link
Copy Markdown
Contributor Author

/verified

@opendatahub-tests-bot opendatahub-tests-bot added the Verified Verified pr in Jenkins label Apr 28, 2025
@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented Apr 28, 2025

"""

Walkthrough

The changes introduce certificate verification for HTTPS requests in the TrustyAIServiceClient class. A new instance attribute, cert_path, is initialized in the constructor by generating a CA bundle file using the Kubernetes client. The _send_request method now uses this CA bundle for the verify parameter in HTTP requests, replacing the previous hardcoded disabling of verification. This update involves importing the CA bundle creation utility and modifying the relevant methods to support secure server certificate verification.

Changes

File(s) Change Summary
tests/model_explainability/trustyai_service/trustyai_service_utils.py Imported create_ca_bundle_file; added cert_path attribute to TrustyAIServiceClient; updated _send_request to use cert_path for HTTPS certificate verification instead of disabling verification.

Poem

In the warren of code, a bundle was spun,
Certificates gathered, the work is now done.
No more skipping checks, we verify with care,
Secure little rabbits, aware and aware!
With trust in our tunnels, we hop with delight,
For safety and service now shine ever bright.
🐇🔒
"""


📜 Recent review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 3c48db5 and 235e48d.

📒 Files selected for processing (1)
  • tests/model_explainability/trustyai_service/trustyai_service_utils.py (3 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • tests/model_explainability/trustyai_service/trustyai_service_utils.py
✨ Finishing Touches
  • 📝 Generate Docstrings

🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 73fd84e and 8e97065.

📒 Files selected for processing (1)
  • tests/model_explainability/trustyai_service/trustyai_service_utils.py (3 hunks)
🧰 Additional context used
🧬 Code Graph Analysis (1)
tests/model_explainability/trustyai_service/trustyai_service_utils.py (1)
utilities/certificates_utils.py (1)
  • create_ca_bundle_file (21-64)
🔇 Additional comments (2)
tests/model_explainability/trustyai_service/trustyai_service_utils.py (2)

15-15: Good addition of certificate utility import

Adding the import for create_ca_bundle_file is necessary for implementing certificate verification in HTTPS requests. This aligns with the PR's objective to enhance security when communicating with the TrustyAI Service.


61-61:

Details

✅ Verification successful

Certificate path initialization looks good

Initializing the certificate path in the constructor is appropriate as it needs to be done once per client instance.

Let's verify how empty certificate paths are handled:


🏁 Script executed:

#!/bin/bash
# Check error handling if cert path is empty
grep -A 20 "create_ca_bundle_file" utilities/certificates_utils.py | grep -A 5 "LOGGER.warning"

Length of output: 93


🏁 Script executed:

#!/bin/bash
# Locate and inspect create_ca_bundle_file definition and its return behavior
grep -R "def create_ca_bundle_file" -n utilities/certificates_utils.py -A30

Length of output: 1087


🏁 Script executed:

#!/bin/bash
# Retrieve the remainder of create_ca_bundle_file to inspect warning and return behavior
sed -n '52,120p' utilities/certificates_utils.py

Length of output: 1820


Certificate path initialization verified

The create_ca_bundle_file function returns a valid file path when the secret exists and otherwise logs a warning (Could not find <secret> secret) before returning an empty string. Initializing self.cert_path once in the constructor correctly handles both cases without further changes required.

@adolfo-ab adolfo-ab force-pushed the add-trustyai-certs branch from 3c48db5 to 235e48d Compare April 29, 2025 09:06
@adolfo-ab
Copy link
Copy Markdown
Contributor Author

/verified

@opendatahub-tests-bot opendatahub-tests-bot added the Verified Verified pr in Jenkins label Apr 29, 2025
@rnetser rnetser merged commit 8fdbcf7 into opendatahub-io:main Apr 29, 2025
14 checks passed
@github-actions
Copy link
Copy Markdown

Status of building tag latest: success.
Status of pushing tag latest to image registry: success.

dbasunag pushed a commit to dbasunag/opendatahub-tests that referenced this pull request May 8, 2025
dbasunag pushed a commit to dbasunag/opendatahub-tests that referenced this pull request May 8, 2025
dbasunag added a commit that referenced this pull request May 20, 2025
* updates to test_registering_model() based on previous review comments

* [do-not-review]must-gather collection at failure point

updates! 1176505

updates! 12d9c08

updates! 12d9c08

updates! 65e0213

* [ModelRegistry] ensure RunAsUser and RunAsGroup are not set explicitly (#226)

updates! 4813f2b

updates! 20cd457

updates! b126825

updates! 809cca7

* Lock file maintenance (#241)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* RHOAIENG-22058: chore(workbenches): add test_create_simple_notebook to smoke (#238)

* Remove uv cache from dockerfile to support running in envs like openshift-ci (#239)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: remove uv cache from dockerfile

* `is_managed_cluster` fix condition (#243)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: replace iter with list

* fix: add logger info

* RHOAIENG-22057: fix(workbenches): correct the check for spawned workbench (#242)

There can only ever be a single workbench pod started.

Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>

* RHOAIENG-22057: fix(workbenches): check for internal image registry and adjust the image path accordingly (#244)

* now yielding TimeoutSampler get_pods_by_isvc_label func output and handling raised ResourceNotFoundError (#237)

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [model server] add auth test to upgrade (#245)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: add auth test to upgrade

* feat: add auth test to upgrade

feat: add auth test to upgrade

* fix: dsci name in func

* [pre-commit.ci] pre-commit autoupdate (#246)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.4 → v0.11.5](astral-sh/ruff-pre-commit@v0.11.4...v0.11.5)
- [github.com/gitleaks/gitleaks: v8.24.2 → v8.24.3](gitleaks/gitleaks@v8.24.2...v8.24.3)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix add-remove-labels workflow (#249)

* Add Cluster sanity checks before test execution (#235)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity add readme

* fix: tix str typo

* fix: address comments

* fix: address review comments

* fix: address comment

* fix: use dsci from global config

* fix: remove duplicate fixture

* add labeler to add labels to prs based on areas impacted (#248)

* on rebase clean commented-by- labels (#251)

* [model registry] update namespace code and rearrange tests (#247)

* updates to test_registering_model() based on previous review comments

* update namespace code and rearrange tests

* remove unnecessary argument from function call (#255)

* on rebase clean commented-by- labels

* remove unnecessary argument from function call

* feat: add ocp_interop marker (#260)

* Lock file maintenance (#259)

* Lock file maintenance

* fix: add marshmallow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* [pre-commit.ci] pre-commit autoupdate (#263)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.5 → v0.11.6](astral-sh/ruff-pre-commit@v0.11.5...v0.11.6)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* feat: add upgrade tests (#258)

* Remove flake8 ignore list (#265)

* fix: remove flake8 ignore

* fix: remove flake8 ignore

* [model server] Remove pod pre-checks for image pull and fix `TestServerlessScaleToZero` (#256)

* fix: update tests

* fix: update tests

* fix: update tests

* fix: save test dep name

* fix: minio mm external route

* fix: address comemnt

* fix: address comemnt

* fix: address comemnt

* Update python-dependencies (major) (#267)

* Update python-dependencies

* fix: marshmellow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* Adding Test For InferenceService Zero Initial Scale (#262)

* adding test for zero initial scale

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* fixing precommit error

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* using label_selectors when getting deployment

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* adding argument names to func call and running pre-commit on all files

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* fixing bug in ovms_kserve_inference_service function that was preventing isvcs from being created with 0 min-replicas

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* feat: move interop marker (#268)

* feat: Add upgrade tests for TrustyAIService (#250)

* feat: Add upgrade tests for TrustyAIService

* Move upgrade README.md to docs/UPGRADE.md

* fix: reuse kwargs in TrustyAIService fixture

* fix: address comments, reuse kwargs, add docstrings

---------

Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix ns deletion logic  (#272)

* fix: fix resource deletion fixture logic

* fix: fix resource deletion fixture logic

* feat: fail on missing operators (#257)

* fix: update tests

* fix: update tests

* feat: fail on missing operators

* fix: rename to dependent

* fix: address comment

* fix: add log on failure

* fix: type in raise

* fix: remove MR check

* fix: remove MR check

* fix: use package scope

* Add basic InferenceGraph deployment check (#233)

* Add basic InferenceGraph deployment check

This adds a test that deploys an InferenceGraph (IG), sends an inference request to the IG and verifies that the request succeeds.

The deployed InferenceGraph is based on the example on the KServe documentation available in the following URL: https://kserve.github.io/website/0.15/modelserving/inference_graph/image_pipeline/. The example was adapted to run in openvino (which is a supported server in ODH), rather than TorchServe.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Use cloud storage in InferenceGraph test

Use cloud storage for the models, instead of OCI

* Feedback: Ruth

* Feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Apply Ruth suggestions

Acknowledgement to @rnester for these changes.

* More feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* fix: address 503 (#274)

* [model server] Move to using unprivileged_client in tests (#273)

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* fix: unpri selection

* Update MinIo pod privileges to run on ocp 4.19 (#277)

* fix: add securityContext for minio pod

* fix: minio on 4.19

* [model server]  add multi node args check (#276)

* feat: add multi node args

* feat: add multi node args

* fix: add wait on delete

* fix: update new test

* [pre-commit.ci] pre-commit autoupdate (#279)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.6 → v0.11.7](astral-sh/ruff-pre-commit@v0.11.6...v0.11.7)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* `verify_no_failed_pods` - exclude container failures when model mesh deployment (#278)

* fix: mm container

* fix: update condition

* feat: add test for incorrect DB TLS config in Trusty AI (#221)

* feat: add test for incorrect DB TLS config in Trusty AI

* refactor: remove unused method from utils

* feat: move TrustyAI test to own file

* refactor: change name of db fixtures and deduplicate code

* TrustyAI Service creation code refactor into own method
* Move db secret setter to utils
* Remove test from test_fairness as test moved to own file

* docs: add description to TrustyAI invalid DB TLS config test

* fix: check TrustyAIService container for Terminated status in lastStatus

* fix: change name of terminal_state getter function

* fix: change to a valid certificate and check for service failure

* fix: address PR 221 reviewer feedback

* revert wait_for_pods to wait_for_mariadb_pods
* improve error checking logic
* remove un-necessary wrapper function

* docs: add docstring to create_trustyai_service method

* docs: add docstring to trustyai_service_with_invalid_db_cert

* fix: fix invalid return type for trustyai_db_ca_secret

* feat: use retry decorator in validate trustyai_service_db_conn_failure method

* fix: remove unnecessary return from validate db_conn_failure method

* docs: add spacing between lines of docstring

* refactor: create constants trustyai metrics and db storage config

* refactor: address reviewer feedback

- change docstring to correct formatting
- remove len(0) check
- no templating for error text

* fix: use regex instead of in operator to check for error condition

* docs: add correct formatting to docstrings

* fix: use namespace.name instead of namespace in Pod.get

* fix: remove \s from regex to check for spaces

* refactor: add Raises section in docstring and use single string for pytest.fail

* feat: use raise instead of pytest.fail

- create new exception TooManyPodsError
- create new exception UnexpectedFailureError
- replace pytest.fail with raise and handle exceptions in retry
-

* fix: change default of teardown to True in TrustyAIService

* docs: correct typo in trustyai docstring

* docs: fix raises in docs and fix formatting

* fix: fix create_trustyai_service namespace args issue

* docs: add default for name arg in create tai svc func

* [model server] Fix runtime request.param name to use external route (#280)

* fix: fix param name

* fix: fix param name

* feat: add certs when sending requests to TrustyAIService (#266)

* Wait for pods to be in running state before attempting to create ModelRegistry (#270)

* on rebase clean commented-by- labels

* Wait for pods to be in running state before attempting to create ModelRegistry

* Address Exception in thread Thread-1 (_monitor) error (#286)

* chore(deps): lock file maintenance (#287)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* [pre-commit.ci] pre-commit autoupdate (#292)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.7 → v0.11.8](astral-sh/ruff-pre-commit@v0.11.7...v0.11.8)
- [github.com/gitleaks/gitleaks: v8.24.3 → v8.25.1](gitleaks/gitleaks@v8.24.3...v8.25.1)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* Wait for dsc and dsci ready state in cluster_sanity check (#293)

* fix(workbenches): implement get_username for OpenShift <=4.14 (#275)

Turns out SelfSubjectReview is only available starting OpenShift 4.15.

fixup incorporate User resource
* RedHatQE/openshift-python-wrapper#2387

fixup incorporate SelfSubjectReview resource
* RedHatQE/openshift-python-wrapper#2389

Co-authored-by: Debarati Basu-Nag <dbasunag@redhat.com>

* replace the bot account with one owned by testdevops (#291)

* Fix for post upgarde operator check (#297)

Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>

* Add test for Model Registry RBAC for SA token (#296)

* feat: add RBAC test for SA token

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: address review comments

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: incorporate coderabbit suggestions

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove unneeded variable

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove excessive logs

Signed-off-by: lugi0 <lgiorgi@redhat.com>

---------

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* Support /build-push-pr-image comment to push image to quay for testing via jenkins (#290)

updates! 678b389

* Add tests for model_artifact update validations (#284)

* Add tests for model_artifact update validations

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* updates fixing pre-commit

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* update package

* minor updates

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* address review comments

updates! 50ec24b

updates! f3a6c3e

updates! 792156f

updates! 399aa10

updates! 5080e3b

updates! c34f4e7

updates! a1d7baa

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Signed-off-by: lugi0 <lgiorgi@redhat.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Jiri Daněk <jdanek@redhat.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>
Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>
Co-authored-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Adolfo Aguirrezabal <aaguirre@redhat.com>
Co-authored-by: Edgar Hernández <ehernand@redhat.com>
Co-authored-by: Shelton Cyril <sheltoncyril@gmail.com>
Co-authored-by: Milind Waykole <mwaykole@redhat.com>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
sheltoncyril referenced this pull request in sheltoncyril/opendatahub-tests Jun 3, 2025
* updates to test_registering_model() based on previous review comments

* [do-not-review]must-gather collection at failure point

updates! 1176505

updates! 12d9c08

updates! 12d9c08

updates! 65e0213

* [ModelRegistry] ensure RunAsUser and RunAsGroup are not set explicitly (#226)

updates! 4813f2b

updates! 20cd457

updates! b126825

updates! 809cca7

* Lock file maintenance (#241)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* RHOAIENG-22058: chore(workbenches): add test_create_simple_notebook to smoke (#238)

* Remove uv cache from dockerfile to support running in envs like openshift-ci (#239)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: remove uv cache from dockerfile

* `is_managed_cluster` fix condition (#243)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: replace iter with list

* fix: add logger info

* RHOAIENG-22057: fix(workbenches): correct the check for spawned workbench (#242)

There can only ever be a single workbench pod started.

Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>

* RHOAIENG-22057: fix(workbenches): check for internal image registry and adjust the image path accordingly (#244)

* now yielding TimeoutSampler get_pods_by_isvc_label func output and handling raised ResourceNotFoundError (#237)

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [model server] add auth test to upgrade (#245)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: add auth test to upgrade

* feat: add auth test to upgrade

feat: add auth test to upgrade

* fix: dsci name in func

* [pre-commit.ci] pre-commit autoupdate (#246)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.4 → v0.11.5](astral-sh/ruff-pre-commit@v0.11.4...v0.11.5)
- [github.com/gitleaks/gitleaks: v8.24.2 → v8.24.3](gitleaks/gitleaks@v8.24.2...v8.24.3)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix add-remove-labels workflow (#249)

* Add Cluster sanity checks before test execution (#235)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity add readme

* fix: tix str typo

* fix: address comments

* fix: address review comments

* fix: address comment

* fix: use dsci from global config

* fix: remove duplicate fixture

* add labeler to add labels to prs based on areas impacted (#248)

* on rebase clean commented-by- labels (#251)

* [model registry] update namespace code and rearrange tests (#247)

* updates to test_registering_model() based on previous review comments

* update namespace code and rearrange tests

* remove unnecessary argument from function call (#255)

* on rebase clean commented-by- labels

* remove unnecessary argument from function call

* feat: add ocp_interop marker (#260)

* Lock file maintenance (#259)

* Lock file maintenance

* fix: add marshmallow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* [pre-commit.ci] pre-commit autoupdate (#263)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.5 → v0.11.6](astral-sh/ruff-pre-commit@v0.11.5...v0.11.6)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* feat: add upgrade tests (#258)

* Remove flake8 ignore list (#265)

* fix: remove flake8 ignore

* fix: remove flake8 ignore

* [model server] Remove pod pre-checks for image pull and fix `TestServerlessScaleToZero` (#256)

* fix: update tests

* fix: update tests

* fix: update tests

* fix: save test dep name

* fix: minio mm external route

* fix: address comemnt

* fix: address comemnt

* fix: address comemnt

* Update python-dependencies (major) (#267)

* Update python-dependencies

* fix: marshmellow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* Adding Test For InferenceService Zero Initial Scale (#262)

* adding test for zero initial scale

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* fixing precommit error

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* using label_selectors when getting deployment

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* adding argument names to func call and running pre-commit on all files

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* fixing bug in ovms_kserve_inference_service function that was preventing isvcs from being created with 0 min-replicas

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* feat: move interop marker (#268)

* feat: Add upgrade tests for TrustyAIService (#250)

* feat: Add upgrade tests for TrustyAIService

* Move upgrade README.md to docs/UPGRADE.md

* fix: reuse kwargs in TrustyAIService fixture

* fix: address comments, reuse kwargs, add docstrings

---------

Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix ns deletion logic  (#272)

* fix: fix resource deletion fixture logic

* fix: fix resource deletion fixture logic

* feat: fail on missing operators (#257)

* fix: update tests

* fix: update tests

* feat: fail on missing operators

* fix: rename to dependent

* fix: address comment

* fix: add log on failure

* fix: type in raise

* fix: remove MR check

* fix: remove MR check

* fix: use package scope

* Add basic InferenceGraph deployment check (#233)

* Add basic InferenceGraph deployment check

This adds a test that deploys an InferenceGraph (IG), sends an inference request to the IG and verifies that the request succeeds.

The deployed InferenceGraph is based on the example on the KServe documentation available in the following URL: https://kserve.github.io/website/0.15/modelserving/inference_graph/image_pipeline/. The example was adapted to run in openvino (which is a supported server in ODH), rather than TorchServe.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Use cloud storage in InferenceGraph test

Use cloud storage for the models, instead of OCI

* Feedback: Ruth

* Feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Apply Ruth suggestions

Acknowledgement to @rnester for these changes.

* More feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* fix: address 503 (#274)

* [model server] Move to using unprivileged_client in tests (#273)

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* fix: unpri selection

* Update MinIo pod privileges to run on ocp 4.19 (#277)

* fix: add securityContext for minio pod

* fix: minio on 4.19

* [model server]  add multi node args check (#276)

* feat: add multi node args

* feat: add multi node args

* fix: add wait on delete

* fix: update new test

* [pre-commit.ci] pre-commit autoupdate (#279)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.6 → v0.11.7](astral-sh/ruff-pre-commit@v0.11.6...v0.11.7)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* `verify_no_failed_pods` - exclude container failures when model mesh deployment (#278)

* fix: mm container

* fix: update condition

* feat: add test for incorrect DB TLS config in Trusty AI (#221)

* feat: add test for incorrect DB TLS config in Trusty AI

* refactor: remove unused method from utils

* feat: move TrustyAI test to own file

* refactor: change name of db fixtures and deduplicate code

* TrustyAI Service creation code refactor into own method
* Move db secret setter to utils
* Remove test from test_fairness as test moved to own file

* docs: add description to TrustyAI invalid DB TLS config test

* fix: check TrustyAIService container for Terminated status in lastStatus

* fix: change name of terminal_state getter function

* fix: change to a valid certificate and check for service failure

* fix: address PR 221 reviewer feedback

* revert wait_for_pods to wait_for_mariadb_pods
* improve error checking logic
* remove un-necessary wrapper function

* docs: add docstring to create_trustyai_service method

* docs: add docstring to trustyai_service_with_invalid_db_cert

* fix: fix invalid return type for trustyai_db_ca_secret

* feat: use retry decorator in validate trustyai_service_db_conn_failure method

* fix: remove unnecessary return from validate db_conn_failure method

* docs: add spacing between lines of docstring

* refactor: create constants trustyai metrics and db storage config

* refactor: address reviewer feedback

- change docstring to correct formatting
- remove len(0) check
- no templating for error text

* fix: use regex instead of in operator to check for error condition

* docs: add correct formatting to docstrings

* fix: use namespace.name instead of namespace in Pod.get

* fix: remove \s from regex to check for spaces

* refactor: add Raises section in docstring and use single string for pytest.fail

* feat: use raise instead of pytest.fail

- create new exception TooManyPodsError
- create new exception UnexpectedFailureError
- replace pytest.fail with raise and handle exceptions in retry
-

* fix: change default of teardown to True in TrustyAIService

* docs: correct typo in trustyai docstring

* docs: fix raises in docs and fix formatting

* fix: fix create_trustyai_service namespace args issue

* docs: add default for name arg in create tai svc func

* [model server] Fix runtime request.param name to use external route (#280)

* fix: fix param name

* fix: fix param name

* feat: add certs when sending requests to TrustyAIService (#266)

* Wait for pods to be in running state before attempting to create ModelRegistry (#270)

* on rebase clean commented-by- labels

* Wait for pods to be in running state before attempting to create ModelRegistry

* Address Exception in thread Thread-1 (_monitor) error (opendatahub-io#286)

* chore(deps): lock file maintenance (opendatahub-io#287)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* [pre-commit.ci] pre-commit autoupdate (opendatahub-io#292)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.7 → v0.11.8](astral-sh/ruff-pre-commit@v0.11.7...v0.11.8)
- [github.com/gitleaks/gitleaks: v8.24.3 → v8.25.1](gitleaks/gitleaks@v8.24.3...v8.25.1)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* Wait for dsc and dsci ready state in cluster_sanity check (opendatahub-io#293)

* fix(workbenches): implement get_username for OpenShift <=4.14 (#275)

Turns out SelfSubjectReview is only available starting OpenShift 4.15.

fixup incorporate User resource
* RedHatQE/openshift-python-wrapper#2387

fixup incorporate SelfSubjectReview resource
* RedHatQE/openshift-python-wrapper#2389

Co-authored-by: Debarati Basu-Nag <dbasunag@redhat.com>

* replace the bot account with one owned by testdevops (opendatahub-io#291)

* Fix for post upgarde operator check (opendatahub-io#297)

Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>

* Add test for Model Registry RBAC for SA token (opendatahub-io#296)

* feat: add RBAC test for SA token

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: address review comments

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: incorporate coderabbit suggestions

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove unneeded variable

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove excessive logs

Signed-off-by: lugi0 <lgiorgi@redhat.com>

---------

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* Support /build-push-pr-image comment to push image to quay for testing via jenkins (opendatahub-io#290)

updates! 678b389

* Add tests for model_artifact update validations (#284)

* Add tests for model_artifact update validations

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* updates fixing pre-commit

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* update package

* minor updates

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* address review comments

updates! 50ec24b

updates! f3a6c3e

updates! 792156f

updates! 399aa10

updates! 5080e3b

updates! c34f4e7

updates! a1d7baa

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Signed-off-by: lugi0 <lgiorgi@redhat.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Jiri Daněk <jdanek@redhat.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>
Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>
Co-authored-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Adolfo Aguirrezabal <aaguirre@redhat.com>
Co-authored-by: Edgar Hernández <ehernand@redhat.com>
Co-authored-by: Shelton Cyril <sheltoncyril@gmail.com>
Co-authored-by: Milind Waykole <mwaykole@redhat.com>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
adolfo-ab added a commit to adolfo-ab/opendatahub-tests that referenced this pull request Jun 11, 2025
* updates to test_registering_model() based on previous review comments

* [do-not-review]must-gather collection at failure point

updates! 1176505

updates! 12d9c08

updates! 12d9c08

updates! 65e0213

* [ModelRegistry] ensure RunAsUser and RunAsGroup are not set explicitly (opendatahub-io#226)

updates! 4813f2b

updates! 20cd457

updates! b126825

updates! 809cca7

* Lock file maintenance (opendatahub-io#241)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* RHOAIENG-22058: chore(workbenches): add test_create_simple_notebook to smoke (opendatahub-io#238)

* Remove uv cache from dockerfile to support running in envs like openshift-ci (opendatahub-io#239)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: remove uv cache from dockerfile

* `is_managed_cluster` fix condition (opendatahub-io#243)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* fix: replace iter with list

* fix: add logger info

* RHOAIENG-22057: fix(workbenches): correct the check for spawned workbench (opendatahub-io#242)

There can only ever be a single workbench pod started.

Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>

* RHOAIENG-22057: fix(workbenches): check for internal image registry and adjust the image path accordingly (opendatahub-io#244)

* now yielding TimeoutSampler get_pods_by_isvc_label func output and handling raised ResourceNotFoundError (opendatahub-io#237)

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [model server] add auth test to upgrade (opendatahub-io#245)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: add auth test to upgrade

* feat: add auth test to upgrade

feat: add auth test to upgrade

* fix: dsci name in func

* [pre-commit.ci] pre-commit autoupdate (opendatahub-io#246)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.4 → v0.11.5](astral-sh/ruff-pre-commit@v0.11.4...v0.11.5)
- [github.com/gitleaks/gitleaks: v8.24.2 → v8.24.3](gitleaks/gitleaks@v8.24.2...v8.24.3)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix add-remove-labels workflow (opendatahub-io#249)

* Add Cluster sanity checks before test execution (opendatahub-io#235)

* Create size-labeler.yml

* Delete .github/workflows/size-labeler.yml

* model mesh - add auth tests

* xx

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity

* feat: cluster sanity add readme

* fix: tix str typo

* fix: address comments

* fix: address review comments

* fix: address comment

* fix: use dsci from global config

* fix: remove duplicate fixture

* add labeler to add labels to prs based on areas impacted (opendatahub-io#248)

* on rebase clean commented-by- labels (opendatahub-io#251)

* [model registry] update namespace code and rearrange tests (opendatahub-io#247)

* updates to test_registering_model() based on previous review comments

* update namespace code and rearrange tests

* remove unnecessary argument from function call (opendatahub-io#255)

* on rebase clean commented-by- labels

* remove unnecessary argument from function call

* feat: add ocp_interop marker (opendatahub-io#260)

* Lock file maintenance (opendatahub-io#259)

* Lock file maintenance

* fix: add marshmallow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* [pre-commit.ci] pre-commit autoupdate (opendatahub-io#263)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.5 → v0.11.6](astral-sh/ruff-pre-commit@v0.11.5...v0.11.6)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* feat: add upgrade tests (opendatahub-io#258)

* Remove flake8 ignore list (opendatahub-io#265)

* fix: remove flake8 ignore

* fix: remove flake8 ignore

* [model server] Remove pod pre-checks for image pull and fix `TestServerlessScaleToZero` (opendatahub-io#256)

* fix: update tests

* fix: update tests

* fix: update tests

* fix: save test dep name

* fix: minio mm external route

* fix: address comemnt

* fix: address comemnt

* fix: address comemnt

* Update python-dependencies (major) (opendatahub-io#267)

* Update python-dependencies

* fix: marshmellow version

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: rnetser <rnetser@redhat.com>

* Adding Test For InferenceService Zero Initial Scale (opendatahub-io#262)

* adding test for zero initial scale

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* fixing precommit error

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* using label_selectors when getting deployment

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* adding argument names to func call and running pre-commit on all files

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

* fixing bug in ovms_kserve_inference_service function that was preventing isvcs from being created with 0 min-replicas

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* feat: move interop marker (opendatahub-io#268)

* feat: Add upgrade tests for TrustyAIService (opendatahub-io#250)

* feat: Add upgrade tests for TrustyAIService

* Move upgrade README.md to docs/UPGRADE.md

* fix: reuse kwargs in TrustyAIService fixture

* fix: address comments, reuse kwargs, add docstrings

---------

Co-authored-by: Ruth Netser <rnetser@redhat.com>

* Fix ns deletion logic  (opendatahub-io#272)

* fix: fix resource deletion fixture logic

* fix: fix resource deletion fixture logic

* feat: fail on missing operators (opendatahub-io#257)

* fix: update tests

* fix: update tests

* feat: fail on missing operators

* fix: rename to dependent

* fix: address comment

* fix: add log on failure

* fix: type in raise

* fix: remove MR check

* fix: remove MR check

* fix: use package scope

* Add basic InferenceGraph deployment check (opendatahub-io#233)

* Add basic InferenceGraph deployment check

This adds a test that deploys an InferenceGraph (IG), sends an inference request to the IG and verifies that the request succeeds.

The deployed InferenceGraph is based on the example on the KServe documentation available in the following URL: https://kserve.github.io/website/0.15/modelserving/inference_graph/image_pipeline/. The example was adapted to run in openvino (which is a supported server in ODH), rather than TorchServe.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Use cloud storage in InferenceGraph test

Use cloud storage for the models, instead of OCI

* Feedback: Ruth

* Feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Apply Ruth suggestions

Acknowledgement to @rnester for these changes.

* More feedback: Ruth

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* fix: address 503 (opendatahub-io#274)

* [model server] Move to using unprivileged_client in tests (opendatahub-io#273)

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* feat: use unprivileged_client

* fix: unpri selection

* Update MinIo pod privileges to run on ocp 4.19 (opendatahub-io#277)

* fix: add securityContext for minio pod

* fix: minio on 4.19

* [model server]  add multi node args check (opendatahub-io#276)

* feat: add multi node args

* feat: add multi node args

* fix: add wait on delete

* fix: update new test

* [pre-commit.ci] pre-commit autoupdate (opendatahub-io#279)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.6 → v0.11.7](astral-sh/ruff-pre-commit@v0.11.6...v0.11.7)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>

* `verify_no_failed_pods` - exclude container failures when model mesh deployment (opendatahub-io#278)

* fix: mm container

* fix: update condition

* feat: add test for incorrect DB TLS config in Trusty AI (opendatahub-io#221)

* feat: add test for incorrect DB TLS config in Trusty AI

* refactor: remove unused method from utils

* feat: move TrustyAI test to own file

* refactor: change name of db fixtures and deduplicate code

* TrustyAI Service creation code refactor into own method
* Move db secret setter to utils
* Remove test from test_fairness as test moved to own file

* docs: add description to TrustyAI invalid DB TLS config test

* fix: check TrustyAIService container for Terminated status in lastStatus

* fix: change name of terminal_state getter function

* fix: change to a valid certificate and check for service failure

* fix: address PR 221 reviewer feedback

* revert wait_for_pods to wait_for_mariadb_pods
* improve error checking logic
* remove un-necessary wrapper function

* docs: add docstring to create_trustyai_service method

* docs: add docstring to trustyai_service_with_invalid_db_cert

* fix: fix invalid return type for trustyai_db_ca_secret

* feat: use retry decorator in validate trustyai_service_db_conn_failure method

* fix: remove unnecessary return from validate db_conn_failure method

* docs: add spacing between lines of docstring

* refactor: create constants trustyai metrics and db storage config

* refactor: address reviewer feedback

- change docstring to correct formatting
- remove len(0) check
- no templating for error text

* fix: use regex instead of in operator to check for error condition

* docs: add correct formatting to docstrings

* fix: use namespace.name instead of namespace in Pod.get

* fix: remove \s from regex to check for spaces

* refactor: add Raises section in docstring and use single string for pytest.fail

* feat: use raise instead of pytest.fail

- create new exception TooManyPodsError
- create new exception UnexpectedFailureError
- replace pytest.fail with raise and handle exceptions in retry
-

* fix: change default of teardown to True in TrustyAIService

* docs: correct typo in trustyai docstring

* docs: fix raises in docs and fix formatting

* fix: fix create_trustyai_service namespace args issue

* docs: add default for name arg in create tai svc func

* [model server] Fix runtime request.param name to use external route (opendatahub-io#280)

* fix: fix param name

* fix: fix param name

* feat: add certs when sending requests to TrustyAIService (opendatahub-io#266)

* Wait for pods to be in running state before attempting to create ModelRegistry (opendatahub-io#270)

* on rebase clean commented-by- labels

* Wait for pods to be in running state before attempting to create ModelRegistry

* Address Exception in thread Thread-1 (_monitor) error (opendatahub-io#286)

* chore(deps): lock file maintenance (opendatahub-io#287)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* [pre-commit.ci] pre-commit autoupdate (opendatahub-io#292)

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.11.7 → v0.11.8](astral-sh/ruff-pre-commit@v0.11.7...v0.11.8)
- [github.com/gitleaks/gitleaks: v8.24.3 → v8.25.1](gitleaks/gitleaks@v8.24.3...v8.25.1)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* Wait for dsc and dsci ready state in cluster_sanity check (opendatahub-io#293)

* fix(workbenches): implement get_username for OpenShift <=4.14 (opendatahub-io#275)

Turns out SelfSubjectReview is only available starting OpenShift 4.15.

fixup incorporate User resource
* RedHatQE/openshift-python-wrapper#2387

fixup incorporate SelfSubjectReview resource
* RedHatQE/openshift-python-wrapper#2389

Co-authored-by: Debarati Basu-Nag <dbasunag@redhat.com>

* replace the bot account with one owned by testdevops (opendatahub-io#291)

* Fix for post upgarde operator check (opendatahub-io#297)

Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>

* Add test for Model Registry RBAC for SA token (opendatahub-io#296)

* feat: add RBAC test for SA token

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: address review comments

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: incorporate coderabbit suggestions

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove unneeded variable

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* fix: remove excessive logs

Signed-off-by: lugi0 <lgiorgi@redhat.com>

---------

Signed-off-by: lugi0 <lgiorgi@redhat.com>

* Support /build-push-pr-image comment to push image to quay for testing via jenkins (opendatahub-io#290)

updates! 678b389

* Add tests for model_artifact update validations (opendatahub-io#284)

* Add tests for model_artifact update validations

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* updates fixing pre-commit

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* update package

* minor updates

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* address review comments

updates! 50ec24b

updates! f3a6c3e

updates! 792156f

updates! 399aa10

updates! 5080e3b

updates! c34f4e7

updates! a1d7baa

---------

Signed-off-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Signed-off-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Signed-off-by: lugi0 <lgiorgi@redhat.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Jiri Daněk <jdanek@redhat.com>
Co-authored-by: Ruth Netser <rnetser@redhat.com>
Co-authored-by: Luca Giorgi <lgiorgi@redhat.com>
Co-authored-by: Brett Thompson <196701379+brettmthompson@users.noreply.github.com>
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Adolfo Aguirrezabal <aaguirre@redhat.com>
Co-authored-by: Edgar Hernández <ehernand@redhat.com>
Co-authored-by: Shelton Cyril <sheltoncyril@gmail.com>
Co-authored-by: Milind Waykole <mwaykole@redhat.com>
Co-authored-by: Milind Waykole <mwaykole@mwaykole-thinkpadp1gen4i.bengluru.csb>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants